![]() |
|
Log-Analyse und Auswertung: PC langsam-Verdacht auf MalwareWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #7 |
![]() ![]() | ![]() PC langsam-Verdacht auf Malware ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=1 Results of screen317's Security Check version 0.99.93 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Java(TM) 6 Update 22 Java version 32-bit out of Date! Adobe Flash Player 16.0.0.235 Adobe Reader 10.1.13 Adobe Reader out of Date! Mozilla Firefox (34.0.5) Google Chrome (39.0.2171.71) Google Chrome (39.0.2171.95) ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-01-2015 Ran by HO (administrator) on HO-VAIO on 09-01-2015 22:30:37 Running from C:\Users\HO\Downloads Loaded Profile: HO (Available profiles: HO) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Opera) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (VSee Lab, Inc.) C:\Users\HO\AppData\Roaming\VSeeInstall\vsee.exe (Nokia) C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe (Genie9) C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Citrix Online, a division of Citrix Systems, Inc.) C:\Users\HO\AppData\Local\Citrix\GoToMeeting\2128\g2mstart.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe (Microsoft Corporation) C:\Windows\System32\LogonUI.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Genie9) C:\Program Files\Genie9\Genie Timeline\GenieTimeLineAgent.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277992 2011-11-15] (Realtek Semiconductor) HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [790688 2011-04-29] (Atheros Communications) HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [657568 2011-04-29] (Atheros Commnucations) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2531624 2011-03-04] (Synaptics Incorporated) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277992 2011-11-15] (Realtek Semiconductor) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-12] (Intel Corporation) HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [2757312 2011-02-15] (Sony Corporation) HKLM-x32\...\Run: [PMBVolumeWatcher] => c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation) HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [179976 2013-08-28] (cyberlink) HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-09] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [PowerDVD14Agent] => C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe [795672 2014-11-07] (CyberLink Corp.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-01-15] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-569190459-326481895-3770856800-1001\...\Run: [VSee] => C:\Users\HO\AppData\Roaming\VSeeInstall\vsee.exe [22674968 2014-08-12] (VSee Lab, Inc.) HKU\S-1-5-21-569190459-326481895-3770856800-1001\...\Run: [] => [X] HKU\S-1-5-21-569190459-326481895-3770856800-1001\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-10-02] (Nokia) HKU\S-1-5-21-569190459-326481895-3770856800-1001\...\Run: [GoToMeeting] => C:\Users\HO\AppData\Local\Citrix\GoToMeeting\2128\g2mstart.exe [40304 2014-12-26] (Citrix Online, a division of Citrix Systems, Inc.) HKU\S-1-5-21-569190459-326481895-3770856800-1001\...\MountPoints2: {64318709-472b-11e3-95bc-f0bf975f1bea} - G:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-569190459-326481895-3770856800-1001\...\MountPoints2: {d853c108-46e7-11e3-8c08-f0bf975f1bea} - G:\HTC_Sync_Manager_PC.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-569190459-326481895-3770856800-1001\Software\Microsoft\Internet Explorer\Main,Start Page = CountrySelector - Sony HKU\S-1-5-21-569190459-326481895-3770856800-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = CountrySelector - Sony SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-569190459-326481895-3770856800-1001 -> {21E70A4D-EE68-4D33-9B96-CAEA082328E9} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-21/4?satitle={searchTerms} SearchScopes: HKU\S-1-5-21-569190459-326481895-3770856800-1001 -> {6F1D62BB-A687-4750-A16D-0861C5CE8495} URL = Shopping.com Deutschland - der große Produkt- und Preisvergleich SearchScopes: HKU\S-1-5-21-569190459-326481895-3770856800-1001 -> {AF0246D0-1070-4208-AD72-6A975DE7EEC0} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices BHO: Avira SearchFree Toolbar -> {41564952-412D-5637-4300-7A786E7484D7} -> "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll" No File BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: CmjBrowserHelperObject Object -> {07A11D74-9D25-4fea-A833-8B0D76A5577A} -> C:\Program Files (x86)\Mindjet\MindManager 7\Mm7InternetExplorer.dll (Mindjet) BHO-x32: Avira SearchFree Toolbar -> {41564952-412D-5637-4300-7A786E7484D7} -> "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll" No File BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll" No File Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll" No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 188.93.120.2 8.8.8.8 8.8.4.4 FireFox: ======== FF ProfilePath: C:\Users\HO\AppData\Roaming\Mozilla\Firefox\Profiles\3y4un2ge.default FF SearchEngineOrder.1: SuchMaschine FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll () FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-569190459-326481895-3770856800-1001: @citrixonline.com/appdetectorplugin -> C:\Users\HO\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online) FF Plugin HKU\S-1-5-21-569190459-326481895-3770856800-1001: vsee.com/VSeeDetection -> C:\Users\HO\AppData\Roaming\VSeeInstall\npVSeeDetection.dll (VSee Lab) FF SearchPlugin: C:\Users\HO\AppData\Roaming\Mozilla\Firefox\Profiles\3y4un2ge.default\searchplugins\search_engine.xml Chrome: ======= CHR Profile: C:\Users\HO\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Docs) - C:\Users\HO\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-03] CHR Extension: (Google Drive) - C:\Users\HO\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-03] CHR Extension: (YouTube) - C:\Users\HO\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-03] CHR Extension: (Google Search) - C:\Users\HO\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-03] CHR Extension: (Google Wallet) - C:\Users\HO\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-03] CHR Extension: (Gmail) - C:\Users\HO\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-03] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S4 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [807672 2014-12-09] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-09] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-09] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584 2014-12-09] (Avira Operations GmbH & Co. KG) R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-04-29] (Atheros) [File not signed] R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [91296 2011-04-29] (Atheros Commnucations) [File not signed] S2 CLKMSVC10_9EC60124; C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [243464 2013-08-28] (CyberLink) S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [104096 2011-07-19] (Atheros Communication Inc.) [File not signed] R2 GenieTimelineService; C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe [678976 2013-12-29] (Genie9) R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-04-02] (Nero AG) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) S2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [887000 2011-01-20] (Sony Corporation) R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1642544 2014-02-28] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [43064 2014-10-09] (Avira Operations GmbH & Co. KG) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-09] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation) R2 risdsnpe; C:\Windows\System32\DRIVERS\risdsnxc64.sys [98816 2011-03-07] (REDC) R2 {C5F942FD-1110-4664-86CE-0C6BDA305235}; C:\Program Files (x86)\CyberLink\PowerDVD14\Common\NavFilter\000.fcl [32456 2014-11-07] (CyberLink Corp.) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-09 22:29 - 2015-01-09 22:29 - 00001081 _____ () C:\Users\HO\Downloads\checkup_09012015.txt 2015-01-09 07:53 - 2015-01-09 07:53 - 00852505 _____ () C:\Users\HO\Downloads\SecurityCheck.exe 2015-01-08 22:14 - 2015-01-08 22:14 - 00000000 __SHD () C:\Users\HO\AppData\Local\EmieBrowserModeList 2015-01-08 21:14 - 2015-01-08 21:14 - 00043957 _____ () C:\Users\HO\Downloads\FRST_08012015.txt 2015-01-08 21:12 - 2015-01-08 21:12 - 00001136 _____ () C:\Users\HO\Downloads\JRT_08012015.txt 2015-01-08 21:11 - 2015-01-08 21:11 - 00001136 _____ () C:\Users\HO\Desktop\JRT.txt 2015-01-08 21:07 - 2015-01-08 21:07 - 00000000 ____D () C:\Windows\ERUNT 2015-01-08 21:06 - 2015-01-08 21:06 - 01707939 _____ (Thisisu) C:\Users\HO\Downloads\JRT (1).exe 2015-01-08 21:02 - 2015-01-08 21:02 - 00005496 _____ () C:\Users\HO\Downloads\AdwCleaner[S0]_08012015.txt 2015-01-08 20:53 - 2015-01-08 20:58 - 00000000 ____D () C:\AdwCleaner 2015-01-08 20:48 - 2015-01-08 20:48 - 02191360 _____ () C:\Users\HO\Downloads\AdwCleaner_4.107.exe 2015-01-08 20:47 - 2015-01-08 20:47 - 00001207 _____ () C:\Users\HO\Downloads\mbam_08012015.txt 2015-01-08 19:52 - 2015-01-08 20:59 - 00001220 _____ () C:\Windows\PFRO.log 2015-01-08 19:07 - 2015-01-09 18:55 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-08 19:06 - 2015-01-08 19:06 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-08 19:06 - 2015-01-08 19:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-08 19:06 - 2015-01-08 19:06 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-01-08 19:06 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-08 19:06 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-08 19:06 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-08 19:05 - 2015-01-08 19:06 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\HO\Downloads\mbam-setup-2.0.4.1028.exe 2015-01-07 16:49 - 2015-01-07 16:49 - 00000933 _____ () C:\Users\HO\Downloads\HRS_Buchung (23).ics 2015-01-07 16:38 - 2015-01-07 16:38 - 00017288 _____ () C:\Users\HO\Downloads\gmer logfile_07012015.log 2015-01-07 16:19 - 2015-01-07 16:19 - 00380416 _____ () C:\Users\HO\Downloads\Gmer-19357.exe 2015-01-07 15:04 - 2015-01-07 15:05 - 00050325 _____ () C:\Users\HO\Downloads\Addition.txt 2015-01-07 15:01 - 2015-01-09 22:30 - 00020910 _____ () C:\Users\HO\Downloads\FRST.txt 2015-01-07 15:01 - 2015-01-09 22:30 - 00000000 ____D () C:\FRST 2015-01-07 15:00 - 2015-01-07 15:01 - 02124288 _____ (Farbar) C:\Users\HO\Downloads\FRST64.exe 2015-01-07 14:59 - 2015-01-07 14:59 - 00000466 _____ () C:\Users\HO\Downloads\defogger_disable.log 2015-01-07 14:59 - 2015-01-07 14:59 - 00000000 _____ () C:\Users\HO\defogger_reenable 2015-01-07 14:58 - 2015-01-07 14:58 - 00050477 _____ () C:\Users\HO\Downloads\Defogger.exe 2015-01-07 09:42 - 2015-01-07 09:42 - 00001005 _____ () C:\Users\HO\Downloads\BAHN_Fahrplan (95).ics 2015-01-02 14:16 - 2015-01-02 14:16 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk 2015-01-02 14:15 - 2015-01-02 14:16 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-01-02 14:15 - 2015-01-02 14:16 - 00000000 ____D () C:\Program Files\iTunes 2015-01-02 14:15 - 2015-01-02 14:16 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-01-02 14:15 - 2015-01-02 14:15 - 00000000 ____D () C:\ProgramData\Apple Computer 2015-01-02 14:15 - 2015-01-02 14:15 - 00000000 ____D () C:\Program Files\iPod 2015-01-02 14:14 - 2015-01-02 14:15 - 00000000 ____D () C:\Program Files\Common Files\Apple 2015-01-02 14:14 - 2015-01-02 14:14 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2015-01-02 14:14 - 2015-01-02 14:14 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2015-01-02 14:14 - 2015-01-02 14:14 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2015-01-02 14:13 - 2015-01-02 14:13 - 00000000 ____D () C:\Program Files\Bonjour 2015-01-02 14:13 - 2015-01-02 14:13 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2015-01-01 20:44 - 2015-01-09 15:58 - 00001736 _____ () C:\Windows\setupact.log 2015-01-01 20:44 - 2015-01-01 20:44 - 00000000 _____ () C:\Windows\setuperr.log 2015-01-01 20:17 - 2015-01-01 20:18 - 121820924 _____ () C:\Users\HO\Downloads\iTunes64Setup (8).7z 2015-01-01 20:16 - 2015-01-01 20:16 - 00000000 ____D () C:\Users\HO\Downloads\iTunes64Setup (8) 2015-01-01 17:07 - 2015-01-01 17:20 - 122418480 _____ (Apple Inc.) C:\Users\HO\Downloads\iTunes64Setup (8).exe 2015-01-01 16:55 - 2014-10-15 06:18 - 00077104 _____ (Apple Inc.) C:\Users\HO\Downloads\SetupAdmin.exe 2015-01-01 16:50 - 2015-01-01 16:50 - 00000000 ____D () C:\Users\HO\Downloads\iTunes64Setup (7) 2014-12-29 21:58 - 2014-12-29 22:05 - 122418480 _____ (Apple Inc.) C:\Users\HO\Downloads\iTunes64Setup (7).exe 2014-12-29 10:14 - 2014-12-29 10:14 - 00037888 _____ () C:\Users\HO\Downloads\Burn_down_Template.xls 2014-12-21 22:36 - 2014-12-21 22:36 - 00007605 _____ () C:\Users\HO\AppData\Local\Resmon.ResmonCfg 2014-12-19 07:31 - 2014-12-19 07:35 - 00081408 _____ () C:\Users\HO\Downloads\Businessplan-Excel.xls 2014-12-18 22:49 - 2014-12-18 22:49 - 00289792 _____ () C:\Users\HO\Downloads\Burndown_Sample_Clay.xls 2014-12-18 09:05 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-18 09:05 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-12-17 14:38 - 2014-12-17 14:39 - 00001182 _____ () C:\Users\HO\Downloads\embedded_world_ExhibitionConference.ics 2014-12-13 09:43 - 2014-12-13 09:43 - 01054912 _____ (Adobe) C:\Users\HO\Downloads\install_flashplayer16x32au_chrd_dn_aaa_aih.exe 2014-12-11 23:39 - 2014-12-11 23:39 - 00006433 _____ () C:\Users\HO\Desktop\RuppEnergy_english_SAP_v4 - Verknüpfung.lnk 2014-12-11 13:12 - 2014-12-11 13:12 - 00000000 ____D () C:\Windows\system32\appraiser 2014-12-11 12:23 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2014-12-11 12:23 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2014-12-11 12:23 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2014-12-11 12:23 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2014-12-11 12:23 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2014-12-11 12:23 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2014-12-11 12:23 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2014-12-11 12:23 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2014-12-11 12:23 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2014-12-11 12:23 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2014-12-11 06:38 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2014-12-11 06:38 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2014-12-11 06:38 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-12-11 06:38 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-12-11 06:38 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-12-11 06:38 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-12-11 06:38 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-12-11 06:38 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2014-12-11 06:38 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-12-11 06:38 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-12-11 06:38 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-11 06:38 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-11 06:38 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-12-11 06:38 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-11 06:38 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-12-11 06:38 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-11 06:38 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-12-11 06:38 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-12-11 06:38 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-11 06:38 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-12-11 06:38 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-11 06:38 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-12-11 06:38 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-11 06:38 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-12-11 06:38 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-12-11 06:38 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-12-11 06:38 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-11 06:38 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-12-11 06:38 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-12-11 06:38 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-12-11 06:38 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-11 06:38 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-12-11 06:38 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-12-11 06:38 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-12-11 06:38 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-11 06:38 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-12-11 06:38 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-12-11 06:38 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-12-11 06:38 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-12-11 06:38 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-12-11 06:38 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-12-11 06:38 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-11 06:38 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-12-11 06:38 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-12-11 06:38 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-11 06:38 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-12-11 06:38 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-11 06:38 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-12-11 06:38 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-12-11 06:38 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-12-11 06:38 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-12-11 06:38 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-12-11 06:38 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-11 06:38 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-12-11 06:38 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-12-11 06:38 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-12-11 06:38 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-11 06:38 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-12-11 06:38 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-12-11 06:38 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-12-11 06:38 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-12-11 06:38 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-12-11 06:38 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-11 06:38 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-12-11 06:38 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2014-12-11 06:35 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-12-11 06:35 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-12-11 06:35 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2014-12-11 06:35 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe 2014-12-11 06:35 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2014-12-11 06:35 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2014-12-11 06:35 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2014-12-11 06:35 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2014-12-11 06:35 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2014-12-11 06:35 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2014-12-11 06:35 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2014-12-11 06:35 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2014-12-11 06:35 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2014-12-11 06:35 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-09 22:30 - 2013-11-04 07:46 - 00000000 ____D () C:\Users\HO\Documents\Outlook-Dateien 2015-01-09 22:25 - 2013-11-03 01:31 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-09 22:17 - 2013-11-03 01:31 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-09 21:45 - 2014-02-28 11:59 - 00000544 _____ () C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-569190459-326481895-3770856800-1001.job 2015-01-09 21:31 - 2013-11-02 23:34 - 01469171 _____ () C:\Windows\WindowsUpdate.log 2015-01-09 16:53 - 2013-12-04 23:26 - 00000000 ____D () C:\Users\HO\AppData\Local\HTC MediaHub 2015-01-09 16:53 - 2013-11-03 01:31 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-09 16:52 - 2014-01-13 16:02 - 00000000 ____D () C:\Users\HO\AppData\Local\FreePDF_XP 2015-01-09 16:07 - 2009-07-14 05:45 - 00028848 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-09 16:07 - 2009-07-14 05:45 - 00028848 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-09 15:58 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-09 15:22 - 2013-11-03 10:02 - 00000000 ____D () C:\Users\HO\AppData\Roaming\Skype 2015-01-09 14:13 - 2014-08-12 20:05 - 00001401 _____ () C:\Users\HO\Desktop\GoToMeeting.lnk 2015-01-09 14:13 - 2014-05-23 10:15 - 00002467 _____ () C:\Users\HO\Desktop\GoToMeeting Quick Connect.lnk 2015-01-08 22:14 - 2013-11-03 01:14 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-01-08 22:13 - 2013-11-03 00:59 - 00001421 _____ () C:\Users\HO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-01-08 21:20 - 2013-11-03 14:19 - 00000000 ____D () C:\Users\HO\AppData\Local\CrashDumps 2015-01-08 19:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help 2015-01-08 19:06 - 2013-12-06 22:01 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-07 14:59 - 2013-11-03 00:57 - 00000000 ____D () C:\Users\HO 2015-01-07 08:48 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-06 10:32 - 2014-02-28 11:59 - 00003562 _____ () C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-569190459-326481895-3770856800-1001 2015-01-06 04:36 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-01-02 14:16 - 2014-01-26 11:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-01-01 20:39 - 2014-07-30 14:04 - 00000000 ____D () C:\Users\HO\AppData\Roaming\FileZilla 2015-01-01 20:38 - 2013-11-06 10:04 - 00000000 ____D () C:\Windows\Minidump 2014-12-31 09:29 - 2014-03-05 10:44 - 00555924 _____ () C:\test.xml 2014-12-29 21:43 - 2014-04-18 10:22 - 00000000 ____D () C:\MATS 2014-12-29 08:44 - 2014-09-20 22:08 - 00000000 ____D () C:\Users\HO\Documents\Bluetooth Folder 2014-12-28 19:59 - 2013-11-03 01:00 - 00000000 ____D () C:\Users\HO\AppData\Roaming\Atheros 2014-12-28 19:57 - 2013-11-02 23:29 - 00703214 _____ () C:\Windows\system32\perfh007.dat 2014-12-28 19:57 - 2013-11-02 23:29 - 00150822 _____ () C:\Windows\system32\perfc007.dat 2014-12-28 19:57 - 2009-07-14 06:13 - 01629436 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-19 22:25 - 2014-08-26 20:44 - 00000000 ____D () C:\Users\HO\AppData\Local\Adobe 2014-12-19 22:25 - 2013-11-03 01:31 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-12-19 22:25 - 2013-11-03 01:31 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-12-19 22:25 - 2013-11-03 01:31 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-12-18 15:56 - 2014-09-22 08:59 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-12-18 15:56 - 2013-11-03 00:26 - 00000000 ____D () C:\ProgramData\Skype 2014-12-15 17:58 - 2014-02-09 11:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-12-15 15:49 - 2014-06-24 10:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-12-12 21:20 - 2013-11-03 01:32 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-12-12 18:32 - 2013-11-03 00:12 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-12-12 14:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-12-11 13:12 - 2014-05-06 12:26 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-12-11 13:12 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2014-12-11 13:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-12-11 12:33 - 2013-11-03 02:07 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-12-11 12:32 - 2013-11-03 10:06 - 00000000 ____D () C:\Windows\system32\MRT 2014-12-11 12:25 - 2013-11-03 10:06 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\HO\AppData\Local\Temp\avgnt.exe C:\Users\HO\AppData\Local\Temp\NOSEventMessages.dll C:\Users\HO\AppData\Local\Temp\Quarantine.exe C:\Users\HO\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-17 12:38 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- hi schauber, danke bis hier her... ESET hat einen Trojaner identifiziert Opera habe ich auch deinstallirert und benutzer jetzt firefox Was nun? Arty aus irgendwelchen gründen ist opera langsamer geworden (Vor der Analyse) Mit firefox ist der zugriff aufs Interet schneller Wollte das nur noch kurz bemerken Arty |
Themen zu PC langsam-Verdacht auf Malware |
analyse, anlage, applaus, defekt, defogger, eingefangen, gefangen, gmer, ide, informationen, malwar, malware, messages, seite, seiten, sichers, sicherstellen, tagen, tauchen, unterstützung, usb, virus/trojaner |